Get more replies from employers
Send a job-specific resume in minutes.
Openkyber in the United States seeks a Mobile Engineer to join on a long-term contract in Springfield, Boston, or NY (Hybrid). The role focuses on designing, validating, and operationalizing automated mobile vulnerability scanning and configuration compliance across enterprise devices (iOS/iPadOS and Android).
You will lead PoT activities, evaluate tools, integrate with MDM, SIEM/SOAR, ITSM, and CMDB, and drive full-scale implementation while aligning with regulatory requirements such as NYDFS.
Long Term Contract
The Mobile Device Vulnerability Management & Configuration Compliance Engineer will partner with internal stakeholders to design, validate, and operationalize an automated mobile device vulnerability scanning and configuration compliance capability across enterprise-issued mobile endpoints (iOS/iPadOS and Android). This role leads proof-of-technology (PoT) activities including tool evaluation, architecture validation, security controls mapping, and pilot execution, and drives full-scale implementation through integration with other security tools such as MDM, SIEM/SOAR, ITSM, and asset inventory/CMDB systems.
The engineer will establish and maintain mobile vulnerability management processes aligned to corporate and regulatory requirements, develop continuous compliance and policy enforcement strategies, implement risk-based remediation workflows, and deliver measurable improvements in mobile endpoint security posture.
Mobile OS security fundamentals: iOS/iPadOS and Android security models, patching, permissions, app ecosystems, jailbreak/root detection concepts. Vulnerability management expertise: CVE/patch lifecycle, risk-based prioritization, SLAs, validation, metrics. Configuration compliance: baseline hardening, policy enforcement, continuous compliance monitoring, and drift remediation. Mobility Scanning Tool Experience (hands-on): Qualys Mobile VMDR, Lookout, Workspace One + Microsoft Threat Defense, or equivalent. MDM experience (hands-on): Microsoft Intune, Omnissa Workspace ONE, Jamf Pro, or equivalent. Enterprise integration skills: API integration, data normalization, and automation with SIEM/SOAR/ITSM (e.g., Splunk, Sentinel, QRadar; XSOAR, Sentinel SOAR; ServiceNow). Identity & access: conditional access concepts, device compliance states, SSO, certificates, MFA, posture-based access controls. Scripting/automation: PowerShell and/or Python; familiarity with REST APIs, JSON, OAuth, and secrets management. Security documentation: ability to author PoT plans, architecture diagrams, operational runbooks, and audit evidence. Excellent documentation and stakeholder management skills. Strong analytical and problem-solving skills. Excellent communication and stakeholder management skills; experience presenting PoT results and recommendations. Ability to work independently and across multifunctional teams. Detail-oriented with a focus on process improvement and operational excellence. Ability to manage multiple workstreams (pilot + integration + operations) with minimal supervision. Familiarity with NIST, CIS Benchmarks, DISA STIG (mobile), ISO 27001 control mapping, or similar frameworks.
Bachelor s degree in Cybersecurity, Information Systems, Computer Science, Engineering, or equivalent practical experience.
CompTIA Security+, CySA+ GIAC: GSEC, GMON, or related (if available/appropriate) Qualys/Rapid7/Tenable (or equivalent vulnerability platform certifications where relevant) Governance / Risk / Architecture (bonus) CISSP, CISM, CCSP ITIL Foundation (for ITSM integration and operations maturity)
5 8+ years in cybersecurity/endpoint security, with 2 4+ years specifically in mobile/UEM security, vulnerability management, or compliance engineering.